Description |
This article discusses when FortiGate cannot send logs to FortiAnalyzer with FIPS -CC mode enabled in v7.2.5. |
Scope | FortiGate v7.2.5. |
Solution |
For v7.2.5 and v7.4.0, FIPS FortiGate will do the FortiAnalyzer certificate check. The following error will appear in OFTP debugs on FortiGate:
There are some configuration changes required on both FortiGate and FortiAnalyzer:
Here is the requirement for the certificate: In v7.2.5 the OFTP certificate check has changed. FortiAnalyzer and FIPS-CC mode FortiGate each need to have a certificate signed by the same CA.
CA cert requirement:
FortiGate cert requirement:
Here is a configuration example:
config log fortianalyzer setting set status enable set server "faz.domain.com" set certificate-verification disable set serial "FAZ-VM0000xxxxxx" set certificate "FIPS-FGT-Cert" set upload-option realtime
config system certificate oftp set mode local set local "FAZ-Cert" end
After changing the OFTP setting on FortiAnalyzer, it is necessary to restart the daemon using the command 'diag test application oftpd 99'. If it still does not work, try to change the FortiGate certificate to a wildcard certificate and verify the reason for the failure with the below debug commands:
diagnose debug application oftpd 8 <IP/deviceSerial/deviceName> diagnose debug enable |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.